HackingStolen CredentialsCapture Stored DataData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Lee Valley Tools
bd_9a4c3955773a1f40 · schema v1 · pii pii-v1
Full breach record for Lee Valley Tools →Lee Valley Tools, Ltd. notified consumers of a data breach affecting approximately 435 Vermont residents (nationwide count undisclosed). Unauthorized access to a cloud server between Oct 8, 2024, and Mar 12, 2025, exposed names, addresses, and credit card details (number, expiration, CVV). The company engaged cybersecurity experts, notified law enforcement, and offered 12 months of credit monitoring.
Vermont clock⏱ VT AG >14 bday5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_fead9dabf61f395cIndiana State AGfiled 2025-04-15Verified
- bd_282e04dbb9abf769California State AGfiled 2025-04-09(6d gap)Candidate
- bd_66e2c81b16d18c74New Hampshire State AGfiled 2025-04-09(6d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-04-15-lee-valley-tools-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 15, 2025
- Raw hash
- 4c132d48e0c68b8ff163658db81640124271443ab4b43549db4c873477c47ac5
Reporting entity
- Name
- Lee Valley Toolsnorm: lee valley tools
- Domain
- leevalley.com
Victim entity
- Name
- Lee Valley Toolsnorm: lee valley tools
- Domain
- leevalley.com
Incident
- Discovered
- Mar 12, 2025
- Materiality determined
- —
- Notification sent
- Apr 15, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(34 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.